{"id":413122,"date":"2021-09-08T15:27:59","date_gmt":"2021-09-08T13:27:59","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=413122"},"modified":"2021-09-08T15:33:45","modified_gmt":"2021-09-08T13:33:45","slug":"microsoft-warns-of-office-security-flaw","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/413122-microsoft-warns-of-office-security-flaw.html","title":{"rendered":"Microsoft warns of Office security flaw"},"content":{"rendered":"<p>Microsoft has <strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40444\" target=\"_blank\" rel=\"noopener\">warned<\/a><\/strong> users of a remote code execution vulnerability in MSHTML that malicious actors can exploit to infect a target&#8217;s computer.<\/p>\n<p>Hackers exploit this weakness by sending victims a Microsoft Office file that, once opened, directs the victim to the malicious actor\u2019s website, which features an ActiveX control that downloads malware to the computer.<\/p>\n<p>The vulnerability \u2014 CVE-2021-40444 \u2014 impacts Windows Server versions 2008 and onwards, as well as Windows 7 through Windows 10.<\/p>\n<p>\u201cAn attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine,\u201d Microsoft said.<\/p>\n<p>\u201cThe attacker would then have to convince the user to open the malicious document.\u201d<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">&#x1f4a5;&#x1f4a5;&#x26a1;&#xfe0f;&#x26a1;&#xfe0f;<br \/>\nEXPMON system detected a highly sophisticated <a href=\"https:\/\/twitter.com\/hashtag\/ZERO?src=hash&amp;ref_src=twsrc%5Etfw\">#ZERO<\/a>-DAY ATTACK ITW targeting <a href=\"https:\/\/twitter.com\/hashtag\/Microsoft?src=hash&amp;ref_src=twsrc%5Etfw\">#Microsoft<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/Office?src=hash&amp;ref_src=twsrc%5Etfw\">#Office<\/a> users! At this moment, since there&#8217;s no patch, we strongly recommend that Office users be extremely cautious about Office files &#8211; DO NOT OPEN if not fully trust the source!<\/p>\n<p>\u2014 EXPMON (@EXPMON_) <a href=\"https:\/\/twitter.com\/EXPMON_\/status\/1435309115883020296?ref_src=twsrc%5Etfw\">September 7, 2021<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Multiple cybersecurity investigators reported the vulnerability and exploit to Microsoft.<\/p>\n<p>Haifei Li of EXPMON <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-shares-temp-fix-for-ongoing-office-365-zero-day-attacks\/\" target=\"_blank\" rel=\"noopener\"><strong>spoke to BleepingComputer<\/strong><\/a> and indicated that the method is entirely consistent \u2014 a victim only needs to open the malicious file for infection to occur.<\/p>\n<p>The attack experienced by Li came in the form of a Microsoft Word document (.docx).<\/p>\n<p>Microsoft has published mitigation steps to prevent infection via this exploit but has yet to provide a patch for the vulnerability, advising that users disable all ActiveX controls in Internet Explorer.<\/p>\n<p>The tech company has emphasised the need to keep Microsoft Defender Antivirus and Microsoft Defender for Endpoint up to date as they can both detect and prevent infection via the vulnerability.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now Read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/412858-protonmail-slammed-for-sharing-activists-internet-address-with-police.html\" target=\"_blank\" rel=\"noopener\">ProtonMail slammed for sharing activist\u2019s Internet address with police<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has warned users of a vulnerability that can be triggered by opening a document containing a specially crafted malicious payload.<\/p>\n","protected":false},"author":341076,"featured_media":413128,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[51699,123,6599],"class_list":["post-413122","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-bleeping-computer","tag-microsoft","tag-microsoft-office"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/413122"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=413122"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/413122\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/413128"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=413122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=413122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=413122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}